CVE-2022-43685

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/11/2022
Last modified:
29/04/2025

Description

CKAN through 2.9.6 account takeovers by unauthenticated users when an existing user id is sent via an HTTP POST request. This allows a user to take over an existing account including superuser accounts.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:okfn:ckan:*:*:*:*:*:*:*:* 2.8.12 (excluding)
cpe:2.3:a:okfn:ckan:*:*:*:*:*:*:*:* 2.9.0 (including) 2.9.7 (excluding)